Skip to main navigation Skip to search Skip to main content

Information disclosure and security policy design: a large-scale randomization experiment in Pan-Asia

Research output: Conference PapersRGC 32 - Refereed conference paper (without host publication)peer-review

Abstract

The ever increasing number of cyberattacks motivates us to explore a more effective way to enhance the security awareness of the organizations and the general public. Establishing a ranking scheme of firms against online scams may heighten such awareness to address suboptimal security issues. Recognizing the limited research in Pan-Asia, we are motivated to conduct an exploratory study to understand the cyber security issues in the region. The main objective of this study is to find how organizations react in managing two distinct security issues, spam emission and phishing website hosting, when (1) they become aware of such problems and (2) the information is publicized. We argue that spam emission can be considered as an indicator of improper internal control on botnet and malware infections as well as distorted incentives causing negative externality issues, while phishing website hosting behavior can be attributed as a pure negative externality issues caused by lack of deterrence policy and responsibility. To achieve the research goal, we conducted a randomized field experiment on a total population of 1,262 organizations in six Pan-Asian countries. To construct the organizational security evaluation reports, we collected data from four reputable sources and developed a public security advisory website and an email treatment system. With rigorous econometric analysis, we find heterogeneous treatment effects depending on the characteristics of security incidents. Based on the results, we propose cybersecurity policy directions to address the externality issue.
Original languageEnglish
Publication statusPublished - 19 Jun 2018
Event17th Annual Workshop on the Economics of Information Security (WEIS 2018) - Hotel Grauer Bär, Innsbruck, Austria
Duration: 18 Jun 201819 Jun 2018
https://weis2018.econinfosec.org/
https://weis2018.econinfosec.org/program/

Conference

Conference17th Annual Workshop on the Economics of Information Security (WEIS 2018)
Abbreviated titleWEIS 2018
PlaceAustria
CityInnsbruck
Period18/06/1819/06/18
Internet address

Research Keywords

  • cybersecurity
  • externality
  • policy design
  • spam
  • phishing
  • botnet
  • information security index
  • organizational security
  • randomized field experiment

Fingerprint

Dive into the research topics of 'Information disclosure and security policy design: a large-scale randomization experiment in Pan-Asia'. Together they form a unique fingerprint.

Cite this